Saturday, September 26, 2026
1 change · saas-19.4
Security fixes and vulnerability patches
This fix stops public job applications from overwriting the name of an existing contact when an applicant enters that contact's email address. It protects internal user and contact records from unauthorized changes while still allowing recruitment applications to match by email when appropriate.
Original PR description
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name.…
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name. Steps to reproduce: - Create an internal user and publish a job position. - Apply anonymously using the internal user's email and a different name. - Observe that the internal user's display name is replaced. Cause: `_inverse_partner_email()` handles a partner found from the submitted email as if it had already been explicitly linked to the applicant. It then synchronizes the untrusted applicant values onto that partner. Since public applications are created with elevated privileges, the email only match can modify an internal user's contact. https://github.com/odoo/odoo/blob/3b343f7b865bb1f57802f6df881ce4531d02c1ad/addons/hr_recruitment/models/hr_applicant.py#L228-L247 Solution: Use the applicant details only when the email lookup creates a new partner, and stop synchronization after an implicit email match. This allows applications to remain linked by email without letting the match modify an existing contact, while preserving synchronization for partners already explicitly linked to an applicant. opw-6472303 --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#286107 Forward-Port-Of: odoo/odoo#283546